25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Health-ISAC Warns of Increasing ShinyHunters Healthcare Data Theft Attacks

Health sector organizations have been warned about an increase in successful attacks by the ShinyHunters threat group. In contrast to ransomware actors, ShinyHunters conducts supply chain and identity attacks, targeting cloud SaaS and storage platforms. The group is focused on cloud-scale data exfiltration, with initial access typically achieved by voice-based social engineering (vishing) to reset passwords, MFA, or enroll new devices, according to a recent Health-ISAC cybersecurity alert.

Once account access is gained, they log in to the organization’s Okta, Microsoft Entra, or Google SSO dashboard, which lists all applications the account holder has access to, such as Microsoft 365, Salesforce, Dropbox, Google Drive, and other third-party platforms.  Data is rapidly exfiltrated, and victims are advised about the data theft. ShinyHunters demands a ransom payment to prevent the stolen data from being leaked on the group’s dark web data leak site.

In recent months, ShinyHunters has conducted successful attacks on several healthcare and medtech companies, including the medical device manufacturers Medtronic and iRhythm, and OneMedical, DentaQuest, AdaptHealth, and Him & Hers. Health-ISAC explained that in a recent attack on a health sector organization, ShinyHunters claimed to have conducted vishing attacks on multiple employees, allowing a Microsoft Entra account to be compromised and a significant amount of company data to be exfiltrated from SaaS and internal platforms such as Microsoft 365 and SharePoint.

Health-ISAC has shared practical, high-impact recommendations for healthcare and medtech companies to improve defenses against these types of campaigns, the most important of which involves breaking the attack chain between the vishing call and the SSO account takeover. Helpdesk and IAM support workflows can be hardened by requiring out-of-band identity proofing for any password or MFA reset, or device reenrollment. Procedures should be implemented that require verification of the request by a callback to a previously verified number, and manager approval for any privileged user. It should not be possible to perform the password/MFA reset or device re-enrolment on the same inbound call.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

To harden MFA security against reset abuse, phishing-resistant MFA (FIDO2/WebAuthn security keys or equivalent) should be implemented for admins and high-risk groups, and ideally for all users. SMS/voice MFA and weak fallback methods should be disabled or tightly restricted, and strict controls should be implemented for MFA factor registration.

Since the target is SSO, which provides the keys to the kingdom, Health-ISAC recommends classifying these systems as Tier 0 – the most critical company assets. As such, MFA and compliant devices should be required for accessing sensitive cloud services, legacy authentication should be blocked, administrative portals should be limited to managed devices, and geo-velocity/impossible travel checks implemented.

Extortion is only possible with data exfiltration, so it is vital to closely monitor logs for signs of account takeover and large-scale data access. Health-ISAC recommends centralizing Microsoft Entra sign-in logs, audit logs, and SaaS audit logs into an SIEM and configuring alerts for new device enrolments, MFA factor registration OAuth reset events, new OAuth apps or unusual consent grants, unusual bulk downloads, atypical API calls, and new forwarding rules and mailbox delegation changes.

Healthcare employees may be familiar with traditional phishing attacks, but less familiar with vishing. Vishing should be incorporated into security awareness training programs, and consider running vishing simulations on the workforce, especially on individuals with privileged accounts, helpdesk IT staff, new hires, and remote workers.

Health-ISAC recommends a 30- to 60-day time frame for implementing the recommendations, starting with phishing-resistant MFA for high-risk users, strengthening helpdesk reset procedures, and enforcing conditional access policies. In addition, tabletop exercises should be conducted for containing compromised cloud accounts (token/session revocation).

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist